[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: case of service component in server principals



At 05:35 PM 11/15/00 +0100, Norbert Klasen wrote:
>Hi,
>the GSSAPI mechanism included in the IBM SecureWay Directory Client SDK
>uses tickets in which the service component of the server principal is
>in capital letters, i.e. LDAP/server@REALM. 
>OpenLDAP (with Cyrus SASL and MIT krb5) expects the service to be in
>lower case though, i.e. ldap/server@REALM, and thus aborts with
>"gss_accept_sec_context: Miscellaneous failure; Wrong principal in
>request;"
>rfc1510, 7.2.1 states that the hostname must be in lower case, but what
>about the service name?

It should be lower case as well.

Kurt